445
VMScore

CVE-2017-9134

Published: 21/05/2017 Updated: 26/05/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An information-leakage issue exists on Mimosa Client Radios prior to 2.2.3 and Mimosa Backhaul Radios prior to 2.2.3. There is a page in the web interface that will show you the device's serial number, regardless of whether or not you have logged in. This information-leakage issue is relevant because there is another page (accessible without any authentication) that allows you to remotely factory reset the device simply by entering the serial number.

Vulnerable Product Search on Vulmon Subscribe to Product

mimosa client radios

mimosa backhaul radios